US2025119302A1PendingUtilityA1

Providing User ID Information Stored in a Secure Area of a Mobile Device

Assignee: SAMSUNG ELECTRONICS CO LTDPriority: Oct 4, 2023Filed: Aug 21, 2024Published: Apr 10, 2025
Est. expiryOct 4, 2043(~17.2 yrs left)· nominal 20-yr term from priority
H04L 9/3231H04L 9/3265
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one embodiment, a method includes receiving, at a mobile device of a user and from a server device having a database of trusted reader devices, one or more trusted reader root certificates, each pertaining to one or more particular trusted reader devices. The method further includes receiving, at the mobile device, a request from an external device to provide information regarding the user's identity, wherein this information is stored in a secure hardware portion of the mobile device; receiving, at the mobile device, a certificate chain from the requesting external device; evaluating the received certificate chain relative to one or more trusted reader root certificates; and in response to a determination that the received certificate chain matches a trusted reader root certificates, then granting, to a trusted application on the mobile device, access to the information regarding the user's identity.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, at a mobile device of a user and from a server device comprising a database of trusted reader devices, one or more trusted reader root certificates, each trusted reader root certificate pertaining to one or more particular trusted reader devices;   receiving, at the mobile device, a request from an external device to provide information regarding the user's identity, wherein the information regarding the user's identity is stored in a secure hardware portion of the mobile device;   receiving, at the mobile device, a certificate chain from the requesting external device;   evaluating the received certificate chain from the requesting external device relative to the one or more trusted reader root certificates; and   in response to a determination that the received certificate chain matches one of the one or more trusted reader root certificates, then granting, to a trusted application on the mobile device, access to the information regarding the user's identity.   
     
     
         2 . The method of  claim 1 , further comprising presenting, on a display of the mobile device, an identity of the requesting external device. 
     
     
         3 . The method of  claim 1 , further comprising, in response to a determination that the received certificate chain does not match any of the one or more trusted reader root certificates, then presenting a UI on a display of the mobile device comprising an interactive element that denies or allows the request from the external device. 
     
     
         4 . The method of  claim 3 , wherein the UI further comprises an explanation that the identity of the requesting external device cannot be verified by the mobile device. 
     
     
         5 . The method of  claim 4 , wherein the UI further comprises an identification of specific information requested by the requesting external device. 
     
     
         6 . The method of  claim 1 , further comprising periodically requesting any updated reader root certificates from the server device. 
     
     
         7 . The method of  claim 1 , further comprising:
 determining, by the mobile device, one or more current contexts of the mobile device;   determining, based on the one or more current contexts, a trust score associated with the mobile device; and   providing, to the requesting external device, the trust score.   
     
     
         8 . The method of  claim 7 , wherein the one or more current contexts comprise one or more of: a current location of the mobile device, a time since the mobile device was last unlocked, or a duration of time for which the information regarding the user's identity has been provisioned on the mobile device. 
     
     
         9 . The method of  claim 1 , further comprising, in response to a determination that a battery level of the mobile device has fallen below a predetermined critical level, then:
 powering off a main display of the mobile device;   periodically powering a short-range communication module of the mobile device;   in response to a communication between a reader device and the short-range communication module, then:
 temporarily powering on a trusted processor of the mobile device that is granted access to the secure hardware portion; and 
 temporarily powering on a biometric sensor of the mobile device. 
   
     
     
         10 . The method of  claim 9 , wherein the trusted processor is distinct from a main processor the mobile device that is used to run an operating system on the mobile device. 
     
     
         11 . The method of  claim 9 , further comprising:
 receiving a biometric input to the biometric sensor;   validating the biometric input to an authorized biometric input of the user; and   providing, to the reader device, at least some of the information regarding the user's identity.   
     
     
         12 . The method of  claim 1 , further comprising:
 accessing an identifying certificate from the requesting external device;   determining whether the mobile device has previously provided at least some of the information regarding the user's identity to a device having the identifying certificate;   in response to an affirmative determination, then:
 determining one or more current contexts of the mobile device; and 
 automatically granting, based on the one or more current contexts, the request from the requesting external device. 
   
     
     
         13 . The method of  claim 12 , wherein the one or more current contexts comprise a location of the mobile device. 
     
     
         14 . The method of  claim 12 , wherein automatically granting the request comprises granting the request without activating a display of the mobile device. 
     
     
         15 . The method of  claim 12 , further comprising receiving, from the user, authorization to automatically grant requests from a device that provides the identifying certificate. 
     
     
         16 . The method of  claim 1 , further comprising:
 determining specific information sought in the request from the external device;   accessing, by the trusted application, only the specific information from the information regarding the user's identity that is stored in a secure hardware portion of the mobile device; and   providing, to the external device, only the specific information.   
     
     
         17 . An apparatus comprising: one or more non-transitory computer readable storage media storing instructions; and one or more processors coupled to the one or more non-transitory computer readable storage media and operable to execute the instructions to:
 access, on a mobile device of a user, a request from an external device to provide information regarding the user's identity, wherein the information regarding the user's identity is stored in a secure hardware portion of the mobile device;   access, on the mobile device, one or more trusted reader root certificates, each trusted reader root certificate (1) having been received from a server device comprising a database of trusted reader devices and (2) pertaining to one or more particular trusted reader devices;   access, on the mobile device, a certificate chain received from the requesting external device;   evaluate the received certificate chain from the requesting external device relative to the one or more trusted reader root certificates; and   in response to a determination that the received certificate chain matches one of the one or more trusted reader root certificates, then grant, to a trusted application on the mobile device, access to the information regarding the user's identity.   
     
     
         18 . One or more non-transitory computer readable storage media storing instructions that are operable when executed to:
 access, on a mobile device of a user, a request from an external device to provide information regarding the user's identity, wherein the information regarding the user's identity is stored in a secure hardware portion of the mobile device;   access, on the mobile device, one or more trusted reader root certificates, each trusted reader root certificate (1) having been received from a server device comprising a database of trusted reader devices and (2) pertaining to one or more particular trusted reader devices;   access, on the mobile device, a certificate chain received from the requesting external device;   evaluate the received certificate chain from the requesting external device relative to the one or more trusted reader root certificates; and   in response to a determination that the received certificate chain matches one of the one or more trusted reader root certificates, then grant, to a trusted application on the mobile device, access to the information regarding the user's identity.   
     
     
         19 . The media of  claim 18 , further comprising instructions that are operable when executed to present, on a display of the mobile device, an identity of the requesting external device. 
     
     
         20 . The media of  claim 18 , further comprising instructions that are operable when executed to, in response to a determination that the received certificate chain does not match any of the one or more trusted reader root certificates, then present a UI on a display of the mobile device comprising an interactive element that denies or allows the request from the external device.

Join the waitlist — get patent alerts

Track US2025119302A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.